CVE-2023-22471

CVSS V2 None CVSS V3 None
Description
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the Nextcloud Deck app is upgraded to 1.6.5 or 1.7.3 or 1.8.2.
Overview
  • CVE ID
  • CVE-2023-22471
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-14T01:15:14
  • Last Modified Date
  • 2023-01-24T18:38:42
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:* 1 OR 1.6.5
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:* 1 OR 1.7.0 1.7.3
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:* 1 OR 1.8.0 1.8.2
History
Created Old Value New Value Data Type Notes
2023-01-14 04:15:09 Added to TrackCVE
2023-01-14 04:15:10 Weakness Enumeration new
2023-01-17 14:14:49 2023-01-17T13:24:56 CVE Modified Date updated
2023-01-17 14:14:50 Received Awaiting Analysis Vulnerability Status updated
2023-01-20 17:13:51 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-24 19:14:07 2023-01-24T18:38:42 CVE Modified Date updated
2023-01-24 19:14:07 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-24 19:14:09 CPE Information updated